Getting Data In

What are the capabilities of the Splunk Forwarder license?

FritzWittwer_ol
Contributor

We are running heavy forwarders to accept events from a number of universal forwarders, do some transforms and filtering with props and transforms, and then send them to our indexers.

We'd like to use the forwarder license on them, so we don't have to enable a connection to our license master. What capabilities are enabled with this license? Or more specific, are the functions of the parsing, merging and typing pipelines, according to HowIndexingWorks, available with the forwarding license?

0 Karma

vishaltaneja070
Motivator

Hello @FritzWittwer,

Forwarder license is already included in every splunk package which only allows data forwarding nothing else not even parsing.
The Forwarder license allows forwarding of unlimited data. Unlike a Free license, it enables authentication.

The Forwarder license is available only for instances that simply forward data. It is not valid for use on instances that also perform additional functions, such as indexing.

Forwarder licenses are included with Splunk. You do not need to purchase them separately.

There are several types of forwarders:

The universal forwarder has the Forwarder license applied automatically.
The light forwarder uses the Forwarder license, but you must manually enable it by changing to the Forwarder license group.
The heavy forwarder must also be manually converted to the Forwarder license group. If the heavy forwarder will also be performing indexing, the forwarder must instead have access to an Enterprise license.

Please see the below link:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/TypesofSplunklicenses

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...